Russian State-Sponsored Actors Are Still Getting In Through Bad Router Hygiene: Here's What to Check
Some cyberattacks need a zero-day to make headlines. This one didn't. For years, Russian intelligence has simply walked through open doors: default SNMP community strings left unchanged, Cisco's Smart Install left switched on, routers nobody got around to patching. That activity was significant enough to bring eighteen agencies together on a single warning. NSA, CISA, FBI, and DC3 in the United States joined fourteen international partners, including the UK's NCSC, Australia's ACSC, and Canada's Cyber Centre, to co-sign a joint advisory: AA26-194A, "Improve Router Hygiene to Protect Against Russian State-Sponsored Targeting." When that many agencies put their names on one document, it's worth reading closely. Russian FSB Center 16 actors (tracked in the industry as Berserk Bear, Energetic Bear, Dragonfly, and Static Tundra, among other names) have been opportunistically compromising routers and switches worldwide for over a decade, and they're still finding plenty of them, not through